Executive brief
A vulnerability in Microsoft Office could allow an attacker to run unauthorized code on a user's computer. Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. If exploited, this flaw could allow an attacker to gain full control over the affected system, potentially leading to data theft or the installation of malicious software.
Technical details
This vulnerability is classified as a use-after-free (CWE-416) within Microsoft Office. It occurs when the application continues to use a pointer after it has been freed, which can be leveraged by a local attacker to corrupt memory and execute arbitrary code. The attack vector is local, meaning the attacker must have a presence on the system or entice a user to run a malicious file. According to the CVSS metrics, no elevated privileges or user interaction are required for successful exploitation. Affected versions include Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps across Windows, macOS, and Android platforms.
Affected products
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft 365 Apps for Enterprise
- Microsoft Office for Android
Timeline
- 2025-07-08: advisory: Initial advisory published by Microsoft and NVD.